Researchers develop palm-sized device, built for less than $300, that can steal laptop crypto keys using radio waves leaked by its processor
Context & Ripple Effects
This rig lands mid-way through a run of cheap-hardware exfiltration research covered by the same beat: earlier in 2015 came the $10 KeySweeper USB charger that sniffed Microsoft wireless-keyboard traffic, and Wired's follow-up reporting showed popular wireless keyboards shipping with no encryption at all. What separates this device is the target class — instead of input channels, it goes after cryptographic keys sitting inside the laptop itself, leaked through the processor's own radio emissions.
First-order effects
- Anyone running cryptography on a laptop within radio range of the rig can lose keys with no malware installed, no network connection used, and nothing left in software logs — the compromise happens entirely at the physical layer.
- Because the leak originates in the processor hardware, software patches and endpoint protection do nothing for already-shipped machines; remediation falls to shielding and future silicon designs, not antivirus vendors.
Second-order effects
- The device extends a repeatable playbook — Volkswagen key-fob cloning with cheap radio hardware in 2016, stealing smart-card keys by recording power LEDs in 2023 — pressuring chipmakers to treat electromagnetic emission as a shippable-product defect rather than a lab-only curiosity.
- Enterprises whose perimeter model assumes attackers need a network path now face a class of extraction tooling that needs none, forcing physical-proximity controls into threat models that previously treated the machine's enclosure as the boundary.
Third-order effects
- If the cadence holds — a $10 charger in 2015, fob cloning in 2016, LED-based key theft by 2023 — physical-emission leakage hardens into an assumed threat model for key storage, pushing hardware designers toward emission-resistant components and procurement standards toward testing the physical channel, not just the code.
The trend: Side-channel key extraction keeps getting cheaper and more portable, turning once-laboratory attacks into buildable devices that treat the physical channel around any computing device as compromised.